When to Rotate Passwords

For decades, enterprise IT policy mandated password rotation every 30 to 90 days. Modern security guidance (including NIST Special Publication 800-63B) strongly advises against arbitrary password expiration.

Why Arbitrary Rotation Fails

When forced to change passwords frequently, humans adapt poorly:

Attackers know these patterns. If they crack your base password, they instantly know your future passwords.

When SHOULD You Rotate?

  • Evidence of Compromise: If a service announces a breach, change that password immediately.
  • Malware Infection: If you suspect your device was compromised, rotate all credentials from a clean device.
  • Shared Accounts: When a member leaves a shared access group.

Common Mistakes